EU AI Act enforcement is live: what changed on August 2, 2026 for organizations using Claude
On August 2, 2026 the European Commission's AI Office formally gained its powers to investigate and enforce the EU AI Act's rules for general-purpose AI models. Transparency obligations for AI chatbots, AI-generated content, and deepfakes now apply as well. Fines reach €15 million or 3% of global turnover. Most obligations fall on model providers like Anthropic, but organizations deploying Claude and Cowork have their own transparency duties. Here is what actually applies to you.
The date flagged in our Opus 5 coverage has arrived: on August 2, 2026 the European Commission, acting through its AI Office, became formally entitled to exercise its investigation and enforcement powers over providers of general-purpose AI (GPAI) models, and over the AI Act's rules on prohibited practices. The substantive GPAI obligations had technically applied since August 2, 2025, but until now the AI Office lacked the powers to enforce them.
What the AI Office can now do: request technical documentation from model providers, evaluate models directly, require corrective measures, and issue fines. Penalties for GPAI violations reach €15 million or 3% of global annual turnover, whichever is higher. Providers of models placed on the market before August 2, 2025 generally have until August 2, 2027 to comply.
Transparency rules now apply to deployers too. Article 50 of the AI Act became applicable the same day. In practice that means: people must be told when they are interacting with an AI system (chatbot disclosure), AI-generated content must be machine-readably marked, and deepfakes and AI-generated text published to inform the public must be labeled. These duties fall on the organizations deploying AI, not just on Anthropic and its peers.
What this means if you use Claude or Cowork at work. The heavy obligations, model documentation, systemic-risk assessment, incident reporting, sit with Anthropic as the model provider. Anthropic has signed the GPAI Code of Practice, the Commission's compliance vehicle for exactly these duties. Your organization's exposure is narrower but real: customer-facing chatbots built on Claude need clear AI disclosure, AI-generated content that could mislead needs labeling, and prohibited practices (emotion recognition at work, social scoring, manipulative systems) must be off the table regardless of which tool runs them.
The unchanged EU data question. Enforcement going live does not change the data-residency picture we described at the Opus 5 launch: claude.ai and the first-party API run on US infrastructure under Standard Contractual Clauses; genuine EU data residency requires AWS Bedrock EU regions or Google Vertex AI EU, and Claude Cowork has no EU routing option. The AI Act and the GDPR are separate tracks; being fine on one does not cover the other.
A note on proportion. Nothing about day-to-day Claude or Cowork usage changed on August 2. Models did not get switched off, and no new consent banners appeared. What changed is that the rules now have teeth, which makes this the right moment to get your house in order rather than a reason to panic.
Key takeaways
- AI Office enforcement powers over general-purpose AI models active since August 2, 2026
- Fines up to €15 million or 3% of global turnover; documentation requests, model evaluations, and corrective measures now possible
- Article 50 transparency applies: disclose AI chatbots, mark AI-generated content, label deepfakes
- Most obligations hit providers (Anthropic, which signed the GPAI Code of Practice), not end-user organizations
- Deployers keep their own duties: chatbot disclosure, content labeling, no prohibited practices
- EU data residency for Claude still requires Bedrock EU or Vertex AI EU; Cowork has no EU routing option
What should you do?
- 1Inventory where your organization uses AI toward customers, employees, and the public
- 2Add clear AI disclosure to any customer-facing chatbot built on Claude
- 3Label AI-generated content and deepfakes where Article 50 requires it
- 4Ask your legal team to map which AI Act role you hold (provider, deployer, or both) per use case
- 5EU organizations with personal data: keep routing production traffic via Bedrock Frankfurt or Vertex AI EU